Anxiy
Desconectado
Mensajes: 22
|
22cc.1e18: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000011cb3d0) 22cc.1e18: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000011cb6a0) 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd36700000 LB 0x00017000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'bcrypt.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd36350000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd36850000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd385c0000 'C:\WINDOWS\system32\kernel32.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\Windows\System32\WINTRUST.DLL' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\CRYPT32.dll' 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd381d0000 LB 0x0001c000 C:\WINDOWS\system32\imagehlp.dll [fFlags=0x0] 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd38560000 LB 0x0005b000 C:\WINDOWS\system32\sechost.dll [fFlags=0x0] 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\sechost.dll 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd35d50000 LB 0x00023000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd36eb0000 LB 0x00013000 C:\WINDOWS\system32\profapi.dll [fFlags=0x0] 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\profapi.dll 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'wldap32.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\wldap32.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd38680000 LB 0x0005b000 C:\WINDOWS\system32\WLDAP32.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd23950000 LB 0x0002f000 C:\WINDOWS\system32\cryptnet.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\WINDOWS\system32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd23950000 'C:\Windows\System32\cryptnet.dll' 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd3a020000 LB 0x000a6000 C:\WINDOWS\system32\advapi32.dll [fFlags=0x0] 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'rpcrt4.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\sechost.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=311B4CDD9B998ED36E8EA94DCB004D809301CC36 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd382d0000 'C:\WINDOWS\system32\rpcrt4.dll' 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001204f00 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001204f00 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=37D6E98438133375B3719F659EACFE03E2C12276EDBE86FFE7A31D9DF234E8FC 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168) 22cc.1e18: g_pfnWinVerifyTrust=00007ffd36f88890 22cc.1e18: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [redoing WinVerifyTrust] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll' 22cc.1e18: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll [redoing WinVerifyTrust] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\wintrust.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\advapi32.dll' 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000384 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3E30C00BB3189B639214835B4F4C320DEC5BFA77 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3E30C00BB3189B639214835B4F4C320DEC5BFA77 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001204f00 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001204f00 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=E2EF5AC098F166731C9489C0F2C25A1E53814B7F24F0BA3CC3097CC2C1C816F9 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001204b40 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001204b40 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=E2EF5AC098F166731C9489C0F2C25A1E53814B7F24F0BA3CC3097CC2C1C816F9 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900) 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\Wldap32.dll' 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001205200 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5997BB270A09A76A71A9EE8A7ADB154F3D75EEF3 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001204e40 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001204e40 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5997BB270A09A76A71A9EE8A7ADB154F3D75EEF3 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001204b40 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001204b40 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=C90E65F7C65AAA96604C11EA5E2E9E35B45D1E3F23462006389DEBBA84CD1495 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001204c00 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001204c00 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=C90E65F7C65AAA96604C11EA5E2E9E35B45D1E3F23462006389DEBBA84CD1495 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168) 22cc.1e18: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900) 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\cryptnet.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\profapi.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\gpapi.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\sechost.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\imagehlp.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\cryptbase.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll [lacks WinVerifyTrust] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\cryptsp.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\crypt32.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\bcryptprimitives.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rsaenh.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\bcrypt.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\msvcrt.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\msasn1.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\KernelBase.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\WINDOWS\System32\kernel32.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp. 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc. 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x6e864c7a8071ba00 C=ES, O=FNMT-RCM, OU=AC RAIZ FNMT-RCM 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048) 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root 22cc.1e18: supR3HardenedWinIsDesiredRootCA: Adding 0x39bb496d7f0fc200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Development Root Certificate Authority 2014 22cc.1e18: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=44 22cc.1e18: SUPR3HardenedMain: Load Runtime... 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'nsi.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll) WinVerifyTrust 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\rpcrt4.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll' [rcNtRedir=0xc0150008] 22cc.1e18: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\WINDOWS\System32\nsi.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008] 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'... 22cc.1e18: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008] 22cc.1e18: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'. 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) 22cc.1e18: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling] 22cc.1e18: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust] 22cc.1e18: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll 22cc.1e18: supR3HardenedDllNotificationCallback: load 0000000062dd0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust] 22cc.1e18: supR3HardenedDllNotificationCallback: load 0000000062eb0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd37ad0000 LB 0x00008000 C:\WINDOWS\system32\NSI.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\nsi.dll [avoiding WinVerifyTrust] 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd39fb0000 LB 0x00069000 C:\WINDOWS\system32\WS2_32.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\WINDOWS\System32\ws2_32.dll 22cc.1e18: supR3HardenedDllNotificationCallback: load 00007ffd19b00000 LB 0x00552000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled] 22cc.1e18: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll'. 22cc.1e18: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\WINDOWS\System32\nsi.dll' [rescheduled] 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling] 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd19b00000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36f80000 'C:\WINDOWS\system32\Wintrust.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000 'C:\WINDOWS\system32\rsaenh.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd371c0000 'C:\WINDOWS\system32\crypt32.dll' 22cc.1e18: SUPR3HardenedMain: Load TrustedMain... 22cc.1e18: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffd36350000
|